Saturday, December 7, 2024
HomeCyber Security NewsResearchers Found Series of Vulnerabilities in the Software Underlying Microsoft Teams &...

Researchers Found Series of Vulnerabilities in the Software Underlying Microsoft Teams & Other Apps

Published on

SIEM as a Service

Security researchers discovered a series of vulnerabilities in the software underlying popular apps like Discord, Microsoft Teams, Spotify, and many others.

Reports say the group of researchers presented their findings at the Black Hat cybersecurity conference in Las Vegas, explaining how they could have hacked tens of millions of users who use Discord, Microsoft Teams, and the chat app Element by exploiting the software underlying all of them: Electron.

What is Electron? How they are Vulnerable?

It is a free and open-source software framework developed and maintained by GitHub. The framework is designed to create desktop applications using web technologies which are rendered using a flavour of the Chromium browser engine, and a backend using the Node.js runtime environment.

- Advertisement - SIEM as a Service

The researchers reported the vulnerabilities to Electron to find a fix that earned them more than $10,000 in rewards. Reports state that the bugs were fixed before the researchers published their research.

One of the researchers named Aaditya Purani, who discovered these vulnerabilities says “regular users should know that the Electron apps are not the same as their day-to-day browsers,” meaning they are potentially more vulnerable.

In apps like Discord, the bug Purani and his mates found only required them to send a malicious link to a video. In Microsoft Teams, the bug they found could be exploited by inviting a victim to a meeting.

Therefore, in both scenarios, the exploit works if the targets clicked on these links which will lead to full control of the target systems.

“If you are more paranoid, I recommend using the website itself because then you have the protection which Chromium has, which is much larger than the Electron,” Purani said.

Purani confess that he doesn’t run Electron apps, instead opting for using apps like Discord or Spotify inside his browser, which is more hardened against hackers. He also says it’s a good thing to have Electron underlie so many apps because “if you have just one framework which is running all the apps, then you can just focus on hardening that same framework.”

Therefore, Electron is dangerous precisely since users are very likely to click on links shared in Discord or Microsoft Teams. Purani added saying “Don’t click on shady on links”.

Sponsored: Rise of Remote Workers: A Checklist for Securing Your Network – Download Free White paper

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Top Five Industries Most Frequently Targeted by Phishing Attacks

Researchers analyzed phishing attacks from Q3 2023 to Q3 2024 and identified the top...

Russian BlueAlpha APT Exploits Cloudflare Tunnels to Distribute Custom Malware

BlueAlpha, a Russian state-sponsored group, is actively targeting Ukrainian individuals and organizations by using...

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...

Sophisticated Celestial Stealer Targets Browsers to Steal Login Credentials

Researchers discovered Celestial Stealer, a JavaScript-based MaaS infostealer targeting Windows systems that, evading detection...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Top Five Industries Most Frequently Targeted by Phishing Attacks

Researchers analyzed phishing attacks from Q3 2023 to Q3 2024 and identified the top...

Russian BlueAlpha APT Exploits Cloudflare Tunnels to Distribute Custom Malware

BlueAlpha, a Russian state-sponsored group, is actively targeting Ukrainian individuals and organizations by using...

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...